PT-2019-8631 · D Link · D-Link Dcs-1130

Mandar Satam

·

Published

2019-07-02

·

Updated

2023-04-26

·

CVE-2017-8408

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions D-Link DCS-1130 devices (affected versions not specified)
Description An issue was discovered on D-Link DCS-1130 devices, where the device provides a user with the capability of setting a SMB folder for the video clippings recorded by the device. The GET parameters passed in this request result in being passed as commands to a "system" API in the function, thus resulting in command injection on the device. The binary "cgibox" contains the vulnerable function "sub 7EAFC" that receives the values sent by the GET request. The value set in GET parameter user is extracted in function sub 7E49C which is then passed to the vulnerable system API call.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2017-8408

Affected Products

D-Link Dcs-1130